AWS publishes exactly what the SCS-C03 tests and how much each part is worth. Here it is — every domain, its weight, the topics inside it, and the lessons that cover them.
Designing monitoring, alerting, and logging solutions across accounts and organizations, and troubleshooting them when they break.
3 topics in this domain
- Design and implement monitoring and alerting solutions for an AWS account or organization
- Design and implement logging solutions
- Troubleshoot security monitoring, logging, and alerting solutions
Domain 2
Incident Response
Designing and testing incident response plans, and responding to security events with containment, forensics, and root cause analysis.
2 topics in this domain
- Design and test an incident response plan
- Respond to security events
Domain 3
Infrastructure Security
Security controls for network edge services, compute workloads, and network traffic — from WAF rules to hardened AMIs to segmentation.
3 topics in this domain
- Design, implement, and troubleshoot security controls for network edge services
- Design, implement, and troubleshoot security controls for compute workloads
- Design and troubleshoot network security controls
Domain 4
Identity and Access Management
Authentication and authorization strategies for human, application, and system access — the heaviest-weighted domain on the exam.
2 topics in this domain
- Design, implement, and troubleshoot authentication strategies
- Design, implement, and troubleshoot authorization strategies
Encryption in transit and at rest, plus protecting confidential data, credentials, secrets, and cryptographic key materials.
3 topics in this domain
- Design and implement controls for data in transit
- Design and implement controls for data at rest
- Design and implement controls to protect confidential data, credentials, secrets, and cryptographic key materials
Domain 6
Security Foundations and Governance
Multi-account strategy, secure and consistent deployment of cloud resources, and evaluating compliance across AWS environments.
3 topics in this domain
- Develop a strategy to centrally deploy and manage AWS accounts
- Implement a secure and consistent deployment strategy for cloud resources
- Evaluate the compliance of AWS resources